4
CVSSv2

CVE-2020-9076

Published: 15/06/2020 Updated: 20/06/2020
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 6.8 | Impact Score: 5.2 | Exploitability Score: 1.6
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not being properly verified, an attacker can exploit this vulnerability through man-in-the-middle attack to induce user to access malicious URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

huawei p30_firmware

huawei p30_pro_firmware

huawei tony-al00b_firmware

Vendor Advisories

There is an improper authentication vulnerability in some Huawei smartphones Due to the identity of the message sender is not properly verified, an attacker can exploit this vulnerability through man-in-the-middle attack to induce user to access malicious URL (Vulnerability ID: HWPSIRT-2019-12132) This vulnerability has been assigned a Common Vu ...